- Description
- A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Description field of a schematic, which is executed when the BOM Viewer renders the affected content.
- Source
- 4760f414-e1ae-4ff1-bdad-c7a9c3538b79
- NVD status
- Analyzed
- Products
- on-prem_enterprise_server
CVSS 3.1
- Type
- Primary
- Base score
- 4.6
- Impact score
- 2.5
- Exploitability score
- 2.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
- Severity
- MEDIUM
- 4760f414-e1ae-4ff1-bdad-c7a9c3538b79
- CWE-79
- Hype score
- Not currently trending
CVE-2025-27379 - Stored XSS in Altium AES 7.0.3 BOM Viewer allows authenticated attackers to inject JavaScript via Description field. Check: Get-Service | findstr Altium Source: https://t.co/X8DyYPpWgJ
@lsof
22 Jan 2026
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27379 Stored Cross-Site Scripting in Altium AES 7.0.3 BOM Viewer Description Field https://t.co/S65X6ZOg0p
@VulmonFeeds
22 Jan 2026
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-27379 A stored cross-site scripting (XSS) vulnerability in the BOM Viewer in Altium AES 7.0.3 allows an authenticated attacker to inject arbitrary JavaScript into the Descr… https://t.co/gQ1zVQeNnv
@CVEnew
22 Jan 2026
143 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:altium:on-prem_enterprise_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3F31D6A7-989F-4647-AA13-38737112E369",
"versionEndExcluding": "7.0.6",
"versionStartIncluding": "7.0.3",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]